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AMENDMENTS TO THE CLAIMS 

This listing of claims will replace all prior versions, and listings, of claims in the application: 

Listing of Claims: 

1-38. (Canceled) 

39. (Currently amended) An apparatus configured to monitor and audit activity in a 
network, the network utilizes an incremental screen protocol, the apparatus comprising: 

a] an analyzer being configured to analyze intercepted packets, wherein said 
packets are conveyed [[by]] between entities in the network other than the apparatus , and 
being configured to generate analyzed data based on information associated with at least 
some of said packets, the analyzed data being indicative of sessions and being indicative of 
[[an]] the incremental screen protocol used in each of said sessions; 

b) a mirror manager being incrementally updated to reflect a most recent change in 
an on-screen field location of data responsive to the intercepted packets sa i d ana l yz e d data 
for g e n e rat i ng m i rror data r e pr e s e ntat i v e of m i rror s e ss i ons, e ach m i rror s e ss i on 
corr e spond i ng to on e of sa i d s e ss i ons ; an4 

c) a data storage unit comprising a non-transitory computer-readable medium 
accessible thereto for storing the data indicative of sessions and being indicative of the 
incremental screen protocol; and 

d] an audit event analyzer being responsive to said mirror data, said audit event 
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analyzer being configured to generate event data representative of inbound audit events 
and outbound audit events between the other entities in the network , 

said event data including characteristics relating to at le ast the on-screen field 
location of data being part of the inbound audit events and outbound audit events, said a4 
least on-screen field location being representative of at least one operation performed in 
the network, said audit event analyzer being adapted to analyze said event data for 
extracting extracted data from event data representative of an inbound audit event together 
with the characteristics respective of said inbound audit event, and to generate event data 
representative of a united audit event by combining the extracted data with one or more 
fields in event data representative of an outbound audit event based on said characteristics. 

40. (Previously presented) The apparatus of Claim 39, further comprising a business 
event analyzer for processing at least part of said event data representative of outbound, 
inbound and united audit events and generating data representative of business events. 

41. (Previously presented) The apparatus of Claim 40, further comprising an alerts 
manager coupled to the business event analyzer and being responsive to said data 
representative of business events for generating alerts. 
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42. (Previously presented) The apparatus of Claim 41 , wherein the alerts manager is 
configured to generate at least some of the alerts based on predetermined thresholds. 

43. (Previously presented) The apparatus of Claim 39, further comprising a first long 
term storage device for storing at least part of said analyzed data. 

44. (Previously presented) The apparatus of Claim 39, further comprising a second long 
term storage device for storing at least part of said mirror data representative of mirror 
sessions. 

45. (Previously presented) The apparatus of Claim 39, further comprising a compression 
agent for compressing at least part of the mirror data representative of mirror sessions. 

46. (Previously presented) The apparatus of Claim 39, further comprising an encryption 
agent for encrypting at least part of the mirror data representative of mirror sessions. 

47. (Previously presented) The apparatus of Claim 39, further comprising a signature 
agent for digitally signing at least part of the mirror data representative of mirror sessions. 

48. (Currently amended) A method of monitoring and auditing activity in a network, the 
network utilizes an incremental screen protocol, the method comprising: 
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a) analyzing from a first entity intercepted packets conveyed [[by]] between second 
and third entities in the network; 

b) generating analyzed data based on information associated with at least some of 
said packets, the analyzed data being indicative of sessions and being indicative of [[an]] 
the incremental screen protocol used in each of said sessions; 

c) incrementally updating a mirror manager to reflect a most recent change in an on- 
screen field location of data responsive to the intercepted packets sa i d ana l yz e d data 
g e n e rat i ng i n r e sp e ct of on e or mor e of said s e ss i ons m i rror data r e pr e s e ntat i v e of on e or 
mor e m i rror s e ss i ons, e ach m i rror sess i on corr e spond i ng to a s e ss i on ; afl4 

d) storing, in a data storage unit comprising a non-transitory computer-readable 
medium accessible thereto, the data indicative of sessions and being indicative of the 
incremental screen protocol; 

e) generating event data representative of inbound audit events and outbound audit 
events between the second and third entities in the network , said event data including 
characteristics relating to at le ast the on-screen field location of data being part of the 
inbound audit events and outbound audit events, said at le ast on-screen field location being 
representative of at least one operation performed in the network; 

f) extracting extracted data from event data representative of an inbound audit event 
together with the characteristics respective of said inbound audit event; and 
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g) generating event data representative of a united audit event by combining the extracted 
data with one or more fields in event data representative of an outbound audit event based 
on said characteristics. 

49. (Previously presented) The method of Claim 48, further comprising processing at 
least part of said event data representative of outbound, inbound and united audit events 
and generating data representative of business events. 

50. (Previously presented) The method of Claim 49, further comprising responsive to 
said data representative of business events generating alerts in respect of at least one of 
said business events. 

51 . (Previously presented) The method of Claim 50, wherein generating at least some of 
the alerts is based on predetermined thresholds. 

52. (Previously presented) The method of Claim 48, further comprising storing at least 
part of the analyzed data. 

53. (Previously presented) The method of Claim 48, further comprising storing at least 
part of the mirror data representative of mirror sessions. 
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54. (Previously presented) The method of Claim 48, further comprising compressing at 
least part of said mirror data representative of mirror sessions. 

55. (Previously presented) The method of Claim 48, further comprising encrypting at 
least part of said mirror data representative of mirror sessions. 

56. (Previously presented) The method of Claim 48, further comprising digitally signing 
at least part of said mirror data representative of mirror sessions. 

57. (Canceled) 

58. (Currently amended) A computer program product comprising a second non- 
transitory computer -readable us e ab le medium hav i ng storing computer readable program 
code embodied therein for performing steps of Claim 48. 

59. (Previously presented) The apparatus of Claim 39, further comprising a terminal 
responsive to said event data representative of a united audit event for displaying said 
united audit event without requiring that preceding outbound and inbound audit events be 
displayed prior thereto. 



